Free cookie consent management tool by TermsFeed Generator

Series: The Cost of Knowing: Dual Control, Bounded Probing, and the Limits of Forward Simulation

Your simulator has never once been wrong about the past.
Every engineer trusts a simulation right up until it is wrong in a way the simulation itself was built never to notice. This series is an audit of that trust, run against congruence bias, the specific paradox of building a check that can only ever agree with you, and against a real production incident, until the audit produces its own math. Each part stands on a formal result from its own discipline and prices one piece of the same underlying question, without assuming in advance which part, if any, closes it. Every post ends the same way, by naming the exact number at which its own recommendation reverses, because an architecture is only as honest as the failure condition it names, and one that names none was never engineered, only decorated.

4 posts in this series

  1. 1. The Simulation Singularity

    An offline simulator validates cleanly against history, then a correlated-retry burst shatters production. You cannot log a regime that hasn't happened yet. This post proves the modeling tax is a structural trap, not a data-pipeline bug, and Lai and Robbins' 1985 regret floor prices exactly what that comfortable congruence costs: a bill that does not vanish just because you refuse to pay it.

  2. 2. Dual Control and the Weaponized Probe

    Part 1 proved the cost of not exploring. The standard organizational response, scheduling a two-week canary test for the failure you already suspect, is just a second simulator built to agree with you, and under a heavy tail, bounded experiments systematically under-sample the cliff. Feldbaum's 1960 dual control theory supplies the actual fix: a control action engineered to regulate the system and keep testing its own estimates at the same time, permanently, with no scheduled point where it gets to stop, already running at internet scale inside TCP BBR since 2016.

  3. 3. Safe in Probability, Not in Size

    A perpetual probe is a mathematical necessity that terrifies change management. This post builds the boundary a reviewer approves once, a discrete-time stochastic control barrier function, then does what this series always does to its apparatus: names the gap. Bounding the probability of an excursion says nothing about the blast radius. Under a heavy tail, a probability bound alone can certify a system as safe while its worst case runs four orders of magnitude past what a reviewer thought they signed off on.

  4. 4. The Trigger to Stop Simulating

    Three parts in, this series finally answers the question it opened with: not whether to explore, not how safely, but exactly when the case for building the fix stops being patience and starts being negligence. Reframe that decision as what it actually is, a bounded premium paid once for the right to survive an open-ended, heavy-tailed cost, and this series' already-locked numbers say something sharper than "eventually": at this series' base discount rate, every tail weight this series has priced already clears that threshold, though the lightest tail's margin turns out to depend on the discount rate in a way the heavier tails' margins do not.

← Back to all posts